[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Qemu-devel] [PATCH v2 0/1] Bug: Sandbox: libvirt breakdowns qemu guest
From: |
Yi Min Zhao |
Subject: |
[Qemu-devel] [PATCH v2 0/1] Bug: Sandbox: libvirt breakdowns qemu guest |
Date: |
Tue, 15 May 2018 19:33:47 +0800 |
1. Problem Description
======================
If QEMU is built without seccomp support, 'elevateprivileges' remains compiled.
This option of sandbox is treated as an indication for seccomp blacklist support
in libvirt. This behavior is introduced by the libvirt commits 31ca6a5 and
3527f9d. It would make libvirt build wrong QEMU cmdline, and then the guest
startup would fail.
2. Libvirt Log
==============
qemu-system-s390x: -sandbox on,obsolete=deny,elevateprivileges=deny,spawn=deny,\
resourcecontrol=deny: seccomp support is disabled
3. Fixup
========
Compile the code related to sandbox only when CONFIG_SECCOMP is defined.
Yi Min Zhao (1):
sandbox: disable -sandbox if CONFIG_SECCOMP undefined
vl.c | 13 ++++++++-----
1 file changed, 8 insertions(+), 5 deletions(-)
--
Yi Min
- [Qemu-devel] [PATCH v2 0/1] Bug: Sandbox: libvirt breakdowns qemu guest,
Yi Min Zhao <=
- [Qemu-devel] [PATCH v2 1/1] sandbox: disable -sandbox if CONFIG_SECCOMP undefined, Yi Min Zhao, 2018/05/15
- Re: [Qemu-devel] [PATCH v2 1/1] sandbox: disable -sandbox if CONFIG_SECCOMP undefined, Eric Blake, 2018/05/15
- Re: [Qemu-devel] [PATCH v2 1/1] sandbox: disable -sandbox if CONFIG_SECCOMP undefined, Eduardo Otubo, 2018/05/17
- Re: [Qemu-devel] [PATCH v2 1/1] sandbox: disable -sandbox if CONFIG_SECCOMP undefined, Yi Min Zhao, 2018/05/17
- Re: [Qemu-devel] [PATCH v2 1/1] sandbox: disable -sandbox if CONFIG_SECCOMP undefined, Ján Tomko, 2018/05/18
- Re: [Qemu-devel] [PATCH v2 1/1] sandbox: disable -sandbox if CONFIG_SECCOMP undefined, Eduardo Otubo, 2018/05/18
- Re: [Qemu-devel] [PATCH v2 1/1] sandbox: disable -sandbox if CONFIG_SECCOMP undefined, Ján Tomko, 2018/05/18
- Re: [Qemu-devel] [PATCH v2 1/1] sandbox: disable -sandbox if CONFIG_SECCOMP undefined, Yi Min Zhao, 2018/05/19